Courseiva
Security →easyMultiple Choice

220-1102 Security Practice Question

A user receives an email that appears to come from the company's CEO, asking the user to purchase several gift cards for a client appreciation event and to reply with the activation codes. The email address is similar to the CEO's but has an extra character. Which type of social engineering attack is this?

⚠ Common exam trap

A common mix-up: candidates confuse the medium (email vs. phone vs. SMS) with the social engineering goal, leading them to pick vishing or smishing when the attack clearly uses email as the delivery method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Phishing

This is phishing because the attacker uses a deceptive email that mimics a legitimate source (the CEO) to trick the user into revealing sensitive information (gift card activation codes). The extra character in the email address is a classic spoofing technique, making it a subtype often called spear phishing or CEO fraud. Phishing specifically covers email-based social engineering attacks that request credentials, financial data, or other private information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Phishing

    Why this is correct

    Phishing is correct because the attack leverages a fraudulent email message that masquerades as a legitimate communication from the user's own company. The email likely contains a malicious link or attachment designed to steal login credentials, install malware, or trick the recipient into transferring funds. This matches the classic definition of phishing, which specifically involves email as the delivery vector and impersonation of a trusted entity to elicit a sensitive action.

  • ✗

    Vishing

    Why it's wrong here

    Vishing, or voice phishing, is conducted entirely over telephone calls or VoIP systems, not through email messages. Since the attack vector here is explicitly an email, the user cannot be victimized via vishing in this scenario. Vishing typically involves a caller claiming to be from a trusted organization, whereas this incident is a text-based email lure.

  • ✗

    Smishing

    Why it's wrong here

    Smishing is the SMS or text-message counterpart to phishing, delivered through Short Message Service rather than email. Because the attack described originates in the email inbox, it does not meet the technical definition of smishing. Smishing would involve a text message containing a link or phone number, but no such mobile-based vector is present here.

  • ✗

    Pretexting

    Why it's wrong here

    Pretexting relies on creating a fabricated scenario, or pretext, to establish trust and manipulate the victim into revealing information, often through phone calls or in-person interactions. While phishing also involves social engineering, the distinguishing factor here is that the attack is delivered via a fraudulent email, which is phishing's primary hallmark. A pretexting attack would have used the fake email only as a setup for a subsequent interaction, but the email itself is the direct attack vector, making it phishing rather than pretexting.

Go deeper

Related to this question

About these practice questions

This 220-1102 question is part of Courseiva's 925-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1102 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1102 exam.